Skip to main content

Design Pattern: Safely Exporting Data

How to implement a secure end-to-end data export solution

Most organisations need to communicate externally, passing data across organisational boundaries. However, enabling this process, without also risking the leak of sensitive data, can be difficult.

This guidance provides an architecture pattern which will help you to share data, while maintaining the security of your core networks and systems. 







The flow of data in figure 1:

  1. An export of a Document or data object is initiated from the Source System
  2. Sanitisation is performed to remove hidden information from the document. This can require user intervention to tune the level of sanitisation.
  3. Release Authorisation is performed to ensure the document is appropriate for release. This should take into account a number of factors as described above, and might include one or more human review and authorisation steps.
  4. If the Release Authorisation step is successful then (depending on the policy) the document can be Encrypted.
  5. Signing the document for the Release Control can then be invoked if required. 
  6. The Document is then passed to the Release Control, this may check the signature to ensure it has been through Release Authorisation before handing it over to Flow Control.
  7. Flow Control should always directly follow Release Control, to ensure that only data objects passing the Release Authorisation are sent to the External Proxy.
  8. The External Proxy is responsible for sending the document to the Destination System.



Published

Reviewed

Version

1.0